Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2024-22938
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function…
Bosscms
No fix yet
HIGH 7.5
CVE-2024-23629
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access prote…
Mr2600 Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-35836
An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration…
Pocket Wifi 3 Firmware
after 3.009.03_20230504
MEDIUM 5.3
CVE-2023-44401
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `…
Graphql
4.3.7 / 5.1.3+
MEDIUM 6.5
CVE-2024-23675
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST…
Cloud
9.0.8 / 9.1.3+
HIGH 7.5
CVE-2023-52111
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
Emui
No fix yet
MEDIUM 5.3
CVE-2023-4812
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…
GitLab
16.5.5 / 16.6.4+
HIGH 8.8
CVE-2023-5356
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…
GitLab
16.5.6 / 16.6.4+
MEDIUM 5.5
CVE-2023-41994
A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view fro…
macOS
14.0+
MEDIUM 6.5
CVE-2024-21736
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A functio…
S\/4hana Finance
Mitigation only
HIGH 7.2
CVE-2024-21735
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization …
Lt Replication Server
Mitigation only
MEDIUM 5.5
CVE-2023-41779
There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user…
Zxcloud Irai
7.23.32+
CRITICAL 9.8
CVE-2023-52077
Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens …
Nexkey
12.23q4.5+
HIGH 7.6
CVE-2023-5644
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view a…
Wp Mail Log
1.1.3+
HIGH 8.1
CVE-2023-49949
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.
Passwork
6.2.0+
HIGH 7.5
CVE-2022-39337
Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…
Hertzbeat
1.2.1+
MEDIUM 6.3
CVE-2023-50732
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script w…
Xwiki
14.10.7 / 15.2+
MEDIUM 5.3
CVE-2023-50705
An attacker could create malicious requests to obtain sensitive information about the web server.
Uc 500e Firmware
No fix yet
MEDIUM 6.5
CVE-2023-49734
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the…
Superset
2.1.2 / 3.0.2+
MEDIUM 6.8
CVE-2023-6355
Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug.
T…
Controller 7000 Firmware
8.70.231204a / 8.80.231204a+
HIGH 8.2
CVE-2023-41314
The api /api/snapshot and /api/get_log_file would allow unauthenticated access.
It could allow a DoS attack or get arbitrary files from FE node.
Plea…
Doris
2.0.3+
HIGH 8.2
CVE-2023-6837
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to ha…
Api Manager
2.5.0.32 / 2.6.0.52+
HIGH 8.8
CVE-2023-45185
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper author…
I Access Client Solutions
1.1.9.4+
HIGH 8.1
CVE-2023-47320
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…
Silverpeas
6.3.2+
MEDIUM 5.4
CVE-2023-49273
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low pr…
Umbraco Cms
8.18.10 / 10.8.1+
HIGH 8.8
CVE-2020-10676
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace t…
Rancher
2.6.13 / 2.7.4+
HIGH 7.1
CVE-2023-6542
Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages a…
Emarsys Sdk
Mitigation only
HIGH 8.8
CVE-2023-36646
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute p…
Cryptospike
No fix yet
HIGH 8.8
CVE-2023-48859
TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end sec…
A3002ru Firmware
No fix yet
HIGH 7.5
CVE-2023-49239
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet